IndexedVerified

JavaScript/TypeScript Security

JavaScript, TypeScript, and Node.js SAST rules aggregated across verified providers.

Fetch pack

greprules pack fetch javascript-typescript-security --engine opengrep
curl https://api.greprules.io/api/packs/javascript-typescript-security.tar.gz -o javascript-typescript-security.tar.gz

Included rules

835 rules included. Showing 24 loaded rules.
CVE-2026-82871: Tooljet Db Missing Organization Validate Guardcve-2026-82871-tooljet-db-missing-organization-validate-guardCVE-2026-82867: Xss Innerhtml Option Template Interpolationcve-2026-82867-xss-innerhtml-option-template-interpolationCVE-2026-82866: Ssrf Unvalidated Http Prefix Fetchcve-2026-82866-ssrf-unvalidated-http-prefix-fetchCVE-2026-82864: Unbounded Stream Buffer Allocationcve-2026-82864-unbounded-stream-buffer-allocationCVE-2026-82861: Pulumi Urn Substring Parent Checkcve-2026-82861-pulumi-urn-substring-parent-checkCVE-2026-82860: Pulumi Iam Policy Guardrail Missing Inline Typescve-2026-82860-pulumi-iam-policy-guardrail-missing-inline-typesCVE-2026-82858: Untrusted Plan Actions Fallbackcve-2026-82858-untrusted-plan-actions-fallbackCVE-2026-82856: Aws Iam Condition Operator Direct Indexingcve-2026-82856-aws-iam-condition-operator-direct-indexingCVE-2026-82855: Pulumi Policy Unanchored Urn Sibling Checkcve-2026-82855-pulumi-policy-unanchored-urn-sibling-checkCVE-2026-82854: Nodemailer Smtp Size Command Injectioncve-2026-82854-nodemailer-smtp-size-command-injectionCVE-2026-82661: Crlf Injection List Header Commentcve-2026-82661-crlf-injection-list-header-commentCVE-2026-82659: Nodemailer Raw Missing Sandbox Flagscve-2026-82659-nodemailer-raw-missing-sandbox-flagsCVE-2026-82642: Dompurify Incomplete Forbid Tags Iframe Srcdoccve-2026-82642-dompurify-incomplete-forbid-tags-iframe-srcdocCVE-2026-82472: Documenso Missing Cancelled Status Checkcve-2026-82472-documenso-missing-cancelled-status-checkCVE-2026-82456: Mcp Express Unbound Listenercve-2026-82456-mcp-express-unbound-listenerCVE-2026-82454: Jwt Unverified Header Algorithmcve-2026-82454-jwt-unverified-header-algorithmCVE-2026-82417: Unchecked Constructor Isbuffer Callcve-2026-82417-unchecked-constructor-isbuffer-callCVE-2026-82291: Cors Origin Reflection With Credentialscve-2026-82291-cors-origin-reflection-with-credentialsCVE-2026-82287: Cors Untrusted Origin With Credentialscve-2026-82287-cors-untrusted-origin-with-credentialsCVE-2026-81735: Mcp Server Insecure Default Listen All Interfacescve-2026-81735-mcp-server-insecure-default-listen-all-interfacesCVE-2026-81562: Dynamic Child Process Command Injectioncve-2026-81562-dynamic-child-process-command-injectionCVE-2026-80427: Zip Argument Injection Missing Delimitercve-2026-80427-zip-argument-injection-missing-delimiterCVE-2026-79748: Mcphub Unauthorized Stdio Server Creationcve-2026-79748-mcphub-unauthorized-stdio-server-creationCVE-2026-79746: Improper Group Authorization Somecve-2026-79746-improper-group-authorization-some
24 of 835 loaded